Data Processing Agreement

TEMPLATE — PENDING LEGAL REVIEW. Version 0.9 — July 2026. This template is provided for customer review and countersigning discussions; it has not yet been reviewed by a solicitor and does not constitute legal advice.

This Data Processing Agreement ("DPA") forms part of the agreement between JAD Apps, a sole trader trading from Wellington Close, Warsop, Mansfield, Nottinghamshire, NG20 0JL, United Kingdom (the "Processor") and the subscribing organisation identified in the applicable SecureSend Business subscription (the "Controller"), in respect of the SecureSend service, pursuant to Article 28 UK GDPR.

1. Subject matter and duration

Processing of the personal data described in Annex A for the purpose of providing one-time encrypted file-handover, organisation administration, delivery, receipts, and audit evidencing, for the duration of the Controller's subscription plus the wind-down periods in clause 8.

2. Nature and purpose of processing

The Service is architecturally incapable of processing the contents of transferred files: files are encrypted on the Controller's users' devices and never transmitted to the Processor. Processing is limited to transfer metadata, one-time key escrow, delivery contact details, account data, and the audit trail described in the Security Whitepaper §5.

3. Processor obligations

The Processor shall: (a) process personal data only on the Controller's documented instructions, the use of the Service constituting such instructions; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures described in the Security Whitepaper, including client-side encryption, atomic one-time key release, append-only audit storage, and edge-gated administrative access; (d) respect the conditions of clauses 5 and 6 for engaging sub-processors; (e) taking into account the nature of the processing, assist the Controller in responding to data-subject requests; (f) assist the Controller with Articles 32–36 UK GDPR obligations having regard to the information available to it; (g) at the Controller's choice, delete or return personal data at the end of the provision of services per clause 8; (h) make available information necessary to demonstrate compliance, and allow for and contribute to audits conducted by the Controller or its mandated auditor, on reasonable notice.

4. Controller obligations

The Controller warrants it has a lawful basis for the transfers it initiates, is responsible for the accuracy of recipient contact details entered by its users, and acknowledges the audit-trail metadata described in Annex A is retained for 24 months as a feature of the Service.

5. Sub-processors

The Controller grants general authorisation to the sub-processors listed at /legal/subprocessors. The Processor will update that page at least 14 days before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds, in which case the parties will discuss in good faith and the Controller may terminate if unresolved.

6. International transfers

The Service runs on Cloudflare's global edge network. Where processing involves transfers outside the UK, they occur under the sub-processors' UK GDPR-compliant transfer mechanisms (UK Addendum / IDTA or adequacy, as applicable, per each sub-processor's terms).

7. Personal data breach

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably required for the Controller's own Article 33/34 obligations.

8. Deletion and return

On subscription end: sending is disabled; unclaimed transfers burn at their TTL; the audit trail remains exportable by the Controller for 30 days; thereafter organisation data is deleted and the deletion is recorded. Transfer records self-erase 90 days after terminal state regardless. Backups inherent to the platform provider's storage are governed by the sub-processors' terms.

9. Liability and precedence

This DPA is subject to the limitations of liability in the SecureSend Terms of Service. In case of conflict regarding processing of personal data, this DPA prevails.

Annex A — Personal data processed

CategoryData subjectsData
Account/seat dataController's usersEmail address, role, seat status, sign-in identity (Google-verified email)
Transfer metadataController's users; recipientsFile size, sender-supplied label, filename (shown to recipient only, erased ≤90 days after terminal state), timestamps, IP addresses in transfer records
Delivery contactsRecipientsEmail address / phone number as entered by the sender; retained in the audit trail (24 months) for org sends
Billing dataController's billing contactHandled by Stripe; the Processor stores customer/subscription identifiers only
File contentsNot processed — never transmitted to the Processor

Signature blocks

Controller: ______________________ (name, org, date) · Processor: ______________________ (JAD Apps, date)

Contact

support@jadapps.app